Find the item you are reviewing
Each item connects an official passage to a responsible owner, the conditions for using it and the evidence to retain. Open an item to see the full procedure. Record actual results separately in the blank workbook.
143 mapped items · no test results prefilled
No matching items. Clear the filters or try a source ID.
How to read the labels
- Explicit requirement
- The source uses a mandatory requirement. It still needs applicability and evidence.
- Conditional requirement
- The requirement applies when its stated condition holds. An owner must record any non-applicability basis.
- Recommendation
- Google recommends this practice; it is not relabeled as a universal mandatory rule.
- Official procedure
- A documented review or preparation step. Follow the current supported route with the responsible operator.
- Google activity
- A Google-owned review, decision or documented platform behavior. Supplier evidence does not replace Google’s recorded outcome.
01 · Vendor, environment and image prerequisites
60 mapped items. A row’s presence records document coverage only.
VM-01Become an eligible Marketplace vendor
Source locator: “sign up to become a vendor”
- Applies when
- A vendor new to Cloud Marketplace.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Company onboarding details and authorized representative.
- Procedure
- Follow vendor onboarding and retain the enrollment disposition.
- Expected observation
- Vendor enrollment is established independently of product review or publication.
- Keep as evidence
- Enrollment confirmation and owner/date; keep private account details outside the public guide.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-02Complete onboarding validation for every listing
Source locator: “For your first (and all subsequent) listings”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Exact listing identity and current onboarding form.
- Procedure
- Complete the Cloud Marketplace Onboarding Validation Form for this listing, including subsequent listings.
- Expected observation
- A submission record is bound to the exact listing; submission is not approval.
- Keep as evidence
- Form version, listing reference, submission date and Google response in the private handoff.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-03Supply project information for Producer Portal access
Source locator: “complete the Cloud Marketplace Project Info Form”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Project identities and the form supplied by the Marketplace team.
- Procedure
- Complete the Project Info Form; reconcile with SET-06 and SET-07 rather than creating duplicate submissions.
- Expected observation
- The project-information submission and Portal enablement are separately recorded.
- Keep as evidence
- Form receipt and subsequent Partner Engineer enablement confirmation.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-04Review and meet open source policy
Source locator: “comply with Cloud Marketplace open source policy”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Open source compliance owner.
- Before starting
- Exact shipped artifact inventory and the linked current policy.
- Procedure
- Have the owner review the linked recommendations, restrictions and policy against the shipped product. Record unresolved obligations explicitly.
- Expected observation
- A release-specific compliance disposition is recorded with supporting notices and any required remediation.
- Keep as evidence
- Owner review, policy revision/date and approved distributable notices.
Current evidence note: Dependency check pending. The linked open source policy has not been exhaustively mapped by this five-page review.
VM-05Run the delivered product on Compute Engine
Source locator: “deploy software to, and run on, Compute Engine”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Exact VM product and supported deployment configuration.
- Procedure
- Verify that the Marketplace delivery deploys its software to Compute Engine and runs there.
- Expected observation
- The identified deployment is an operating Compute Engine VM product.
- Keep as evidence
- Deployment identity, product process/service observations and scoped test result.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-06Use the Marketplace image and attached license
Source locator: “Cloud Marketplace-hosted image with the attached Compute Engine license”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Candidate image, Marketplace delivery model and product license identity.
- Procedure
- Verify the Marketplace-hosted image and attached Compute Engine license for the exact submitted candidate. Resolve the hosting route with the Partner Engineer.
- Expected observation
- The delivered image and its valid license match the submitted product.
- Keep as evidence
- Image identity, Portal license reference and deployed-instance license evidence.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
VM-07Complete end-to-end testing before submission
Source locator: “tested end to end before you submitted it”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Exact delivery candidate and a customer-reproducible procedure.
- Procedure
- Complete the TEST mapping and retain the full customer path, including post-deployment setup, before claiming this requirement is met.
- Expected observation
- The exact submitted candidate has successful end-to-end evidence without unresolved required steps.
- Keep as evidence
- Candidate identity, run record, expected/actual results and unresolved-step register.
Current evidence note: Pending customer-delivery proof. r232 C7 customer administrator bootstrap remains blocked; local demonstrations do not close it.
VM-08Resolve identified critical security issues
Source locator: “any critical security issues related to the product”
- Applies when
- If the vendor or Google identifies critical product security issues.
- Responsible role
- Security response owner and release owner.
- Before starting
- Confirmed issue, affected release, remediation owner and separate repair/release authority.
- Procedure
- Track the issue to an authorized update and validation. Escalate any Frozen-release constraint to the owner; do not alter r232 through this guide.
- Expected observation
- A verified remediation disposition is available for the affected product.
- Keep as evidence
- Issue reference, affected version, authorized remediation, validation and release disposition.
Current evidence note: Conditional owner check pending. This mapping neither asserts a critical issue nor authorizes security repair.
VM-09Complete the environment and listing setup
Source locator: “Set up your Google Cloud environment”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Applicable SET rows and exact project/listing identities.
- Procedure
- Reconcile the setup rows with the real project and Producer Portal records.
- Expected observation
- Project setup and listing records have named owners and explicit dispositions.
- Keep as evidence
- Completed SET evidence references and pending items.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-10Select and submit the pricing model
Source locator: “select a pricing model”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Commercial pricing owner.
- Before starting
- Approved commercial model and current pricing documentation.
- Procedure
- Review the linked pricing options, select the model and record its Portal review result. The overview says review takes up to four business days and setup may continue in parallel.
- Expected observation
- An exact selected pricing model and its review disposition are recorded.
- Keep as evidence
- Approved pricing specification and dated Portal review status.
Current evidence note: Dependency check pending. Detailed pricing rules are outside the five-page mapping; the timing is guidance, not an approval guarantee.
VM-11Supply a reviewed VM image
Source locator: “Build your VM image”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Reconcile the IMAGE requirements with the exact authorized release candidate and Partner Engineer feedback.
- Expected observation
- The candidate image has a traceable build and validation disposition.
- Keep as evidence
- Image identity and the completed IMAGE evidence references.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
VM-12Review the complete deployment package requirements
Source locator: “Create your deployment package”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Selected deployment method, image and current linked package documentation.
- Procedure
- Review the linked package requirements for the selected deployment method and supply the package-specific checklist and evidence.
- Expected observation
- The exact deployment package has its own complete requirements and review disposition.
- Keep as evidence
- Package identity, method-specific requirements review and Portal disposition.
Current evidence note: Dependency check pending. This guide does not claim complete coverage of the linked deployment-package documentation.
VM-13Track associated Google Cloud consumption
Source locator: “Add a label to track your product's associated consumption”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Current consumption-tracking instructions and authorized package configuration.
- Procedure
- Have the package owner determine and validate the required consumption label against the linked instructions.
- Expected observation
- Required consumption labeling is present and verifiable in the applicable deployment.
- Keep as evidence
- Label requirement reference, package mapping and deployed observation.
Current evidence note: Dependency check pending. The deeper labeling specification is not fully mapped here; no cloud labeling operation was performed.
VM-14Reconcile the testing checklist
Source locator: “Test your product end-to-end”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Exact release and complete TEST rows.
- Procedure
- Link all applicable TEST outcomes to the pre-submission end-to-end requirement in VM-07.
- Expected observation
- Testing coverage and unresolved outcomes are visible before submission.
- Keep as evidence
- TEST workbook and exact candidate binding.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-15Track every required product review
Source locator: “Submit your product to Cloud Marketplace”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Product Details, Pricing and Deployment Package submissions.
- Procedure
- Use the SUB mapping to track each submitted section, Google feedback and issue resolution.
- Expected observation
- Each required review has its own explicit Google disposition.
- Keep as evidence
- Dated Portal statuses and feedback-resolution records.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-16Separate approval from publication
Source locator: “After all reviews are approved”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- All required review approvals and explicit publication authority.
- Procedure
- Record approval of all reviews before any publication decision. The overview describes launch within minutes after approval, not a guaranteed deadline.
- Expected observation
- Approval, publication action and public availability remain distinct recorded states.
- Keep as evidence
- Review approvals, publication authorization, action receipt and public listing observation.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
VM-17Assign post-launch maintenance and monitoring
Source locator: “Maintain and monitor your product after it has launched”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product operations and release owners.
- Before starting
- Support/maintenance ownership and current linked monitoring guidance.
- Procedure
- Review the linked monitoring guidance and record maintenance, monitoring and response responsibilities for the released product.
- Expected observation
- Post-launch responsibilities and observable operating records are defined.
- Keep as evidence
- Maintenance plan, monitoring references, response owner and review cadence.
Current evidence note: Dependency check pending. The linked monitoring documentation is not fully mapped by this review.
VM-18Route onboarding questions to Partner Support Desk
Source locator: “include the word "Marketplace" in your description”
- Applies when
- When onboarding questions require Google assistance.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Exact unresolved question and non-secret product/project reference.
- Procedure
- Submit an authorized Partner Support Desk request with Marketplace in the description and record the response.
- Expected observation
- The request is routed with enough context for Google to answer.
- Keep as evidence
- Private support reference, question, owner and response.
Current evidence note: No support message is sent by this documentation task.
SET-01Separate development and public-image projects
Source locator: “you create two Google Cloud projects”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Approved project naming and ownership.
- Procedure
- Verify the development/testing project uses PARTNER_NAME-dev and the final-image project uses PARTNER_NAME-public, or record Partner Engineer guidance for the actual arrangement.
- Expected observation
- The two project purposes and exact identities are unambiguous.
- Keep as evidence
- Private project-purpose mapping and any Google-confirmed variance.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-02Keep the public project dedicated to images
Source locator: “Don't use this public project for anything other than hosting”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Public-project identity and scoped inventory.
- Procedure
- Verify the public project is used only for final Compute Engine image hosting.
- Expected observation
- No unrelated use is included in the public-project inventory.
- Keep as evidence
- Dated scope review with private identifiers redacted from public material.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-03Verify the specified onboarding access
Source locator: “grant the Editor (roles/editor) and Service Management Admin”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Authorized project IAM owner.
- Before starting
- Current official principal/role pairs and explicit IAM authority outside this guide.
- Procedure
- Have the IAM owner compare both projects with the official onboarding-principal Editor/Service Management Admin grants and producer-principal Config Editor grant. Record discrepancies without changing permissions here.
- Expected observation
- The exact official principal/role/project relationships have an owner-verified disposition.
- Keep as evidence
- Access review reference and dated disposition; no credentials or complete IAM export in the public workbook.
Current evidence note: Pending owner confirmation. This is a documentation check, not authority to grant or broaden access.
SET-04Verify Compute Engine API availability in both projects
Source locator: “For each project, enable the Compute Engine API”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Exact development and public project identities.
- Procedure
- Record the Compute Engine API enablement disposition for each project.
- Expected observation
- Both projects meet the documented API prerequisite.
- Keep as evidence
- Dated API state observations for both projects.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-05Assign the public-project security contact
Source locator: “In the public project only, set a security contact”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Security contact owner.
- Before starting
- Approved security contact and exact public-project identity.
- Procedure
- Verify the public project has the required security notification contact.
- Expected observation
- Security notifications have an assigned, current recipient.
- Keep as evidence
- Private contact configuration confirmation and review date.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-06Complete the Project Info Form once
Source locator: “You only need to complete this form once”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Vendor onboarding owner.
- Before starting
- Projects configured and high-level product details available.
- Procedure
- Provide project/product details through the Project Info Form and link its existing receipt to VM-03; distinguish this one-time form from per-listing onboarding validation.
- Expected observation
- One traceable project-information submission supports Portal onboarding.
- Keep as evidence
- Form receipt, scope and owner/date.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-07Confirm Producer Portal enablement
Source locator: “Your Partner Engineer enables it for you”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Partner Engineer and vendor onboarding owner.
- Before starting
- Completed Project Info Form.
- Procedure
- Obtain the Partner Engineer enablement disposition and verify authorized access to the intended product project.
- Expected observation
- Portal access is established for the intended project.
- Keep as evidence
- Enablement confirmation and access observation without credentials.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-08Prepare the three Portal review tracks
Source locator: “you submit the following information for review”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Exact product entry and named commercial/deployment owners.
- Procedure
- Prepare Product Details, Pricing and Deployment Package as separately tracked review sections.
- Expected observation
- All three tracks have identified inputs, owners and dispositions.
- Keep as evidence
- Three-track review register linked to the SUB rows.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-09Plan independent review tracks early
Source locator: “at any time and in any order”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- The three review requirements and submission schedule.
- Procedure
- Plan the reviews independently: the official page permits any order and says some reviews may take up to two weeks. Start reviewing requirements early.
- Expected observation
- The schedule separates estimated review durations from actual approval dates.
- Keep as evidence
- Owner schedule and actual dated Portal statuses.
Current evidence note: Official timing is an estimate, not a service-level guarantee or approval.
SET-10Establish the product entry before other reviews
Source locator: “you only need to create a Cloud Marketplace entry”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Producer Portal access and chosen public project.
- Procedure
- Confirm the product entry exists in the intended public project; complete remaining details as the separately tracked reviews progress.
- Expected observation
- A stable product entry anchors all review records.
- Keep as evidence
- Product entry reference, project binding and owner.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-11Resolve Portal access through the documented route
Source locator: “If you don't see the link, or can't access the URL”
- Applies when
- If the Producer Portal URL or link is unavailable.
- Responsible role
- Producer Portal owner.
- Before starting
- Intended project, authorized role review and exact access error.
- Procedure
- Verify the selected project and required Editor role with the IAM owner. If access remains unavailable, use Partner Support Desk and include Marketplace in the description.
- Expected observation
- The access issue has a supported resolution or explicit support disposition.
- Keep as evidence
- Error, project/role confirmation and private support reference.
Current evidence note: No access expansion or support request is executed here.
SET-12Confirm the VM product type
Source locator: “Select Virtual machine”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Approved product definition before entry creation.
- Procedure
- Verify the product entry is of type Virtual machine. Record the intended product name and Product ID.
- Expected observation
- The product type matches the VM review being prepared.
- Keep as evidence
- Product type/name/ID confirmation in the private handoff.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-13Verify immutable product identity before creation
Source locator: “The Product ID and product type cannot be changed”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Approved product ID and type.
- Procedure
- Confirm the ID and type before creation because both become immutable; confirm the product name before submission, when it can still be changed.
- Expected observation
- The listing URL identity and product type are deliberately chosen and recorded.
- Keep as evidence
- Owner-confirmed identity decision and current product-entry record.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-14Complete core listing information
Source locator: “Enter a name, tagline, image, and overview description”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product listing owner.
- Before starting
- Approved public product description and image assets.
- Procedure
- In Product Details, complete name, tagline, image and overview description, then check that public claims match the delivered product.
- Expected observation
- The listing contains accurate, reviewable public product information.
- Keep as evidence
- Submitted listing text/assets and owner review.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-15Select at most two listing categories
Source locator: “You can select up to two Category IDs”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product listing owner.
- Before starting
- Applicable Portal category options.
- Procedure
- Choose the relevant Category IDs within the documented limit of two.
- Expected observation
- The categories are relevant and within the allowed count.
- Keep as evidence
- Selected category IDs and product relevance rationale.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-16Complete documentation and product metadata
Source locator: “Complete the Documentation and Product metadata sections”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product listing and documentation owners.
- Before starting
- Current public guide URLs and exact product metadata.
- Procedure
- Complete the Documentation and Product metadata sections and verify the listed documentation links.
- Expected observation
- Reviewers can reach current documentation from the listing.
- Keep as evidence
- Submitted documentation URLs, metadata and link-check result.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-17Use directly relevant search keywords
Source locator: “They must be directly relevant to your product”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product listing owner.
- Before starting
- Proposed Search keywords field.
- Procedure
- Check each search keyword for direct relevance to the product.
- Expected observation
- All submitted search keywords are directly relevant.
- Keep as evidence
- Keyword list and relevance review.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-18Exclude competitor-licensed names from keywords
Source locator: “must not include brand names or product names licensed by competitors”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Product listing owner.
- Before starting
- Proposed search keyword list.
- Procedure
- Review the keywords against the prohibition on brand/product names licensed by competitors.
- Expected observation
- The submitted keyword field avoids the prohibited names.
- Keep as evidence
- Owner-reviewed keyword list.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-19Resolve additional or unavailable categories
Source locator: “might require additional approvals for some categories”
- Applies when
- If a selected category needs extra approval or is not listed in Producer Portal.
- Responsible role
- Producer Portal owner.
- Before starting
- Category choice and Google category-specific instructions.
- Procedure
- Record required extra approvals; request an unlisted category through the special category request form supplied by Google.
- Expected observation
- Category-specific approvals or request outcomes are explicit.
- Keep as evidence
- Category request and approval disposition in private handoff.
Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.
SET-20Track actual Product Details review status
Source locator: “approximately 2-5 business days”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Producer Portal owner.
- Before starting
- Product Details review submission.
- Procedure
- Track the actual review response; the page estimates approximately 2–5 business days for Partner Engineering review and approval.
- Expected observation
- Actual Google status and dates, rather than elapsed time, determine the recorded disposition.
- Keep as evidence
- Submission date and actual review response.
Current evidence note: The estimate does not establish approval or a guaranteed turnaround.
IMG-01Use development-first image review
Source locator: “move it to your public project after your Google Partner Engineer has verified”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Record image development in the development project, Partner Engineer verification, and only then the separately authorized public-image progression.
- Expected observation
- Development, Engineer verification and public-image progression are traceable distinct steps.
- Keep as evidence
- Image identities and dated Partner Engineer disposition.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-02Identify the required Google Cloud tooling
Source locator: “Download the Google Cloud SDK”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Approved isolated image-authoring environment.
- Procedure
- Record the Google Cloud SDK/tooling availability and version for the authorized image workflow.
- Expected observation
- The image workflow has the required tooling identified.
- Keep as evidence
- Tool/version observation and build-environment identity.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-03Use a supported base image and declare architectures
Source locator: “Use one of Google's supported base public images”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Verify the supported Google base public image, installed app packages/configuration, and each offered Arm or x86 image/machine-type pairing. Multiple architecture images may share one product.
- Expected observation
- Every offered architecture has an identified supported base and compatible machine scope.
- Keep as evidence
- Base image and package inventory; architecture/machine matrix.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-04Review supported app-credential retrieval
Source locator: “If you intend to provide support to your customers”
- Applies when
- If customer support is provided under the image instructions.
- Responsible role
- Customer support and deployment owners.
- Before starting
- Approved credential lifecycle and supported customer access design.
- Procedure
- Have the owners review the official instruction to install app-user-credential retrieval scripts and bind it to the supported design. Do not expose credential values in documentation evidence.
- Expected observation
- A supported retrieval path or Partner Engineer-confirmed applicability disposition is recorded.
- Keep as evidence
- Approved procedure, applicability decision and redacted validation.
Current evidence note: Pending exact delivery design/evidence. This guide does not authorize secret retrieval or resolve C7 bootstrap.
IMG-05Identify the licensed-image preparation inputs
Source locator: “Install and customize your software”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Record the target project/zone, primary instance, software configuration and required startup scripts for an authorized image build. The source procedure includes a primary instance with cloud-platform scope; applicability and authority must be reviewed before any future execution.
- Expected observation
- The exact authorized build inputs and startup behavior are reproducible.
- Keep as evidence
- Private build specification, scoped authority and startup-script validation.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-06Bind login setup to deployment metadata
Source locator: “your app must be customized through a server script”
- Applies when
- If the app has a dashboard, database or management console requiring login.
- Responsible role
- Deployment package owner.
- Before starting
- Approved supported login design and the exact deployment package.
- Procedure
- Verify the required server script reads login credentials from instance metadata and configures the username/password during deployment; obtain Partner Engineer guidance where the product uses a different supported model.
- Expected observation
- The applicable login-provisioning behavior is demonstrated for the customer delivery candidate.
- Keep as evidence
- Applicability decision, package/script binding and redacted fresh-deployment test.
Current evidence note: Pending customer-delivery proof. Local admin access does not prove the supported r232 customer bootstrap path.
IMG-07Exclude build-user data and SSH keys from the image
Source locator: “you must clean the input disk”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Review the input disk for build-user directories, SSH keys and temporary installation files before an authorized new image is made. Do not treat deletion of the Frozen disk as a cleanup option.
- Expected observation
- The customer image does not inherit unwanted build-user data or credentials.
- Keep as evidence
- Redacted image-hygiene review and exact candidate identity.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-08Review the disk-preserving cleanup procedure
Source locator: “Delete the VM while preserving the disk”
- Applies when
- For a separately authorized future image build following this official cleanup method.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Review the documented sequence: retain the source disk, use an isolated helper instance with the disk attached as data, clean the mounted disk, and retain the updated disk when the helper is removed. Require exact resource and cleanup authority before execution.
- Expected observation
- An authorized procedure preserves the intended disk throughout cleanup and image creation.
- Keep as evidence
- Approved resource disposition and bounded build/cleanup receipt.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-09Bind the image to its Portal VM license
Source locator: “Under VM license, note the name”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Obtain the exact product VM license from the Deployment Package section and bind that license to the image-creation specification.
- Expected observation
- The image specification uses the exact license assigned to the product.
- Keep as evidence
- Portal license reference, image specification and deployed license result.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-10Use architecture-aware, unique image names
Source locator: “who-vmOS-image-architecture-date”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Check the image name follows the documented who-vmOS-image-architecture-date form with Arm or x86_64, and uses a new unique name for each update.
- Expected observation
- Each release image can be distinguished by its immutable identity and supported architecture.
- Keep as evidence
- Image naming record and version/architecture mapping.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-11Verify image-build project roles and disk identity
Source locator: “roles/compute.storageAdmin”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Authorized IAM and release owners.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Have the owners check the documented public-project Compute Storage Admin and development-project Compute Image User roles, plus source disk project/zone/name and product license. An image description is optional.
- Expected observation
- The planned operation has exact resource inputs and an explicit role/authority disposition.
- Keep as evidence
- Private role review and image input manifest with optional description disposition.
Current evidence note: Pending owner confirmation; this row does not grant IAM permissions, change image access or authorize a build.
IMG-12Apply public-image access only where required
Source locator: “For non-Terraform products that don't use Marketplace owned images”
- Applies when
- Non-Terraform products that do not use Marketplace-owned images. Terraform-only deployment or Marketplace-owned images are excluded by the source note.
- Responsible role
- Deployment owner, IAM owner and Partner Engineer.
- Before starting
- Confirmed deployment method, image ownership model and exact access authority.
- Procedure
- Determine applicability first. Where applicable, have the authorized owner review the official public-image availability instruction without applying access changes through this guide.
- Expected observation
- The conditional access requirement has a justified, Partner Engineer-confirmed disposition; actual access evidence is attached only if applicable.
- Keep as evidence
- Deployment/ownership classification, applicability rationale and private access-review evidence.
Current evidence note: Applicability is pending; do not label this not applicable solely because an image is Frozen. No public-access grant is authorized.
IMG-13Review direct-package random password support
Source locator: “single VM instance with basic firewall rules”
- Applies when
- A simple single-VM deployment with basic firewall rules that needs a generated password.
- Responsible role
- Deployment package owner.
- Before starting
- Selected deployment method and approved login requirements.
- Procedure
- Review the documented direct deployment-package option for automatically including a secure randomized password. Link the decision to the login requirement and GS guidance.
- Expected observation
- The chosen credential-provisioning option is documented and can be validated on the exact candidate.
- Keep as evidence
- Package-method decision and redacted generation/retrieval proof.
Current evidence note: Conditional option, not proof that the current product uses or supports this path. Password values must remain private.
IMG-14Review the mpdev credential option
Source locator: “mpdev tool, which we recommend for most use cases”
- Applies when
- When choosing a deployment-package authoring method.
- Responsible role
- Deployment package owner.
- Before starting
- Deployment requirements and linked package documentation.
- Procedure
- Consider the official mpdev recommendation for most use cases, including automatic inclusion of multiple secure randomized passwords. Record the selected method and current Partner Engineer guidance.
- Expected observation
- The method choice and applicable credential behavior are explicit.
- Keep as evidence
- Method selection, Google guidance and redacted package validation.
Current evidence note: The linked deployment-package documentation remains an owner dependency; no current mpdev integration is inferred.
IMG-15Validate supported post-deployment password retrieval
Source locator: “to obtain the values of any passwords that you created”
- Applies when
- If passwords are created by the selected metadata-based deployment flow.
- Responsible role
- Deployment package owner.
- Before starting
- Approved password name/binding and authorized customer retrieval procedure.
- Procedure
- Verify the documented within-VM metadata retrieval works for the approved customer path and document how the customer obtains credentials without publishing their values.
- Expected observation
- The intended customer can obtain the appropriate generated credentials through the approved path.
- Keep as evidence
- Redacted retrieval result tied to a fresh deployment and documented customer procedure.
Current evidence note: Pending exact delivery proof; no credential retrieval is executed by this documentation task.
IMG-16Validate a fresh instance from the candidate image
Source locator: “Create a VM instance with your newly created image”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Within separately authorized testing, create a fresh instance from the exact candidate image and verify product functionality.
- Expected observation
- Product functionality is observed on a newly deployed candidate, not inferred from a development machine.
- Keep as evidence
- Image/instance binding, functional test steps and actual results.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-17Inspect attached licenses on the test VM
Source locator: “verify that valid licenses are attached”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Deployment package owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Use the authorized instance inspection path to verify valid attached licenses and compare them with the product license record.
- Expected observation
- The actual deployed VM exposes the expected valid product license.
- Keep as evidence
- Redacted instance license observation and product/image identity binding.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-18Resolve the documented Python baseline
Source locator: “Verify that Python 2.6 or greater is installed”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Partner Engineer and release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Record the official wording "Python 2.6 or greater" and obtain current applicability guidance for the selected OS/image. Preserve the observed version; do not install obsolete software to satisfy this wording.
- Expected observation
- Current Google applicability guidance and the exact candidate observation are reconciled.
- Keep as evidence
- Dated Partner Engineer guidance and redacted version observation.
Current evidence note: Official wording retained; applicability pending. Frozen r232 is not modified. Any future image change needs separate release authority.
IMG-19Resolve the documented tooling and service checks
Source locator: “Verify that the following packages are installed”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Partner Engineer and release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Record the source checks for gcloud, SSH client, sshd, curl and DHCP, then obtain current applicability guidance for the selected OS/image and record actual observations. Do not equate a process-name search with functional readiness.
- Expected observation
- Every listed check has a current applicability decision and scoped evidence.
- Keep as evidence
- Five-item applicability/observation record and dated Partner Engineer guidance.
Current evidence note: Official checks are retained as written requirements to reconcile; no package installation or Frozen-image modification is authorized.
IMG-20Inspect residual users and credentials on the test image
Source locator: “no other user directories installed on the instance except for your own”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Release owner.
- Before starting
- Exact candidate image, project and release identities; authorized isolated build or test scope.
- Procedure
- Check the deployed test instance for unintended user directories and residual credentials, preserving the source allowance for the test operator's own directory. Review findings without exposing secret contents.
- Expected observation
- No unintended build-user directories or credentials are inherited by the customer image.
- Keep as evidence
- Redacted hygiene inspection tied to the candidate image.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
IMG-21Resolve the documented monthly image refresh
Source locator: “re-build and re-publish images once every month”
- Applies when
- Every VM Marketplace product.
- Responsible role
- Partner Engineer and release owner.
- Before starting
- Frozen release constraints, base-image update policy and separately authorized future release plan.
- Procedure
- Record the official monthly rebuild/republication instruction when Google updates base public images. Obtain current applicability guidance and an owner-approved future release plan; never rebuild or republish Frozen r232 through this guide.
- Expected observation
- The maintenance obligation, current Google guidance and future-release authority are reconciled explicitly.
- Keep as evidence
- Dated Google guidance, maintenance owner and separate future-release decision.
Current evidence note: Official wording retained; maintenance applicability/plan pending. This instruction does not thaw Frozen r232.
IMG-22Consider the optional image-build automation tool
Source locator: “consider using the open source tool Imagebuilder”
- Applies when
- If automating future authorized VM image builds.
- Responsible role
- Release owner.
- Before starting
- Approved future build scope and chosen toolchain.
- Procedure
- Consider the Imagebuilder option cited by Google and record the chosen approach; adopting it is not a required product change.
- Expected observation
- Automation choice is documented without implying use or validation of Imagebuilder.
- Keep as evidence
- Owner tool-choice disposition and, only if adopted, scoped validation.
Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.
02 · Customer Getting Started documentation
16 mapped items. A row’s presence records document coverage only.
GS-01Maintain a Google Cloud Getting Started page
Source locator: “Every product must be accompanied by a Google Cloud-specific Getting Started document”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Identify the exact proposed VM delivery and the vendor documentation owner.
- Procedure
- Check that a vendor-maintained website page gives detailed Google Cloud deployment and configuration steps for that delivery.
- Expected observation
- A reachable, maintained Google Cloud-specific page identifies its applicable delivery and owner.
- Keep as evidence
- Public URL, page revision or capture date, delivery identity and owner.
Current evidence note: A public deployment guide exists. Its availability does not prove end-to-end reproducibility for the exact Marketplace review delivery.
GS-02Consider permitted Google Cloud co-branding
Source locator: “We suggest that you co-brand the page with the Google Cloud logo”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- An owner decides whether co-branding is appropriate and confirms permitted brand assets.
- Procedure
- Record whether the Getting Started page will use the Google Cloud logo from Partner Network Hub; note that Hub access requires registration.
- Expected observation
- The optional branding choice and asset source are recorded; absence is not classified as failure of a mandatory requirement.
- Keep as evidence
- Branding decision and asset reference, if used.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-03Describe the complete customer journey
Source locator: “starting with the product listing page on Cloud Marketplace”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- The listing entry, deployment package and post-deployment procedure are identified.
- Procedure
- Read the guide from the Marketplace listing through deployment, configuration and post-deployment maintenance; map each transition to the next customer action.
- Expected observation
- The customer can follow an ordered journey without an unexplained transition.
- Keep as evidence
- Reviewed page sections and a journey checklist identifying any missing transition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-04Support the journey with screenshots
Source locator: “We recommend including screenshots throughout the document”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Screenshots are tied to an identified delivery and contain no sensitive information.
- Procedure
- Check that important deployment and operation steps have relevant screenshots alongside text; mark local demonstrations with their actual scope.
- Expected observation
- Screenshots show the action and resulting state without implying an untested Marketplace result.
- Keep as evidence
- Captioned screenshot inventory with delivery identity and capture context.
Current evidence note: Published walkthroughs include local evidence. Local R234 or repaired Admin candidate screenshots are not proof of the frozen r232 Marketplace customer path.
GS-05Explain machine configuration inputs
Source locator: “The recommended machine configuration, disk sizes, and zones.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
- Procedure
- Check that the guide identifies recommended machine type, CPU and memory and distinguishes a reference estimate from a minimum requirement.
- Expected observation
- The customer can choose the input with its purpose and scope understood.
- Keep as evidence
- Page section, input/default inventory and product-owner confirmation for the exact delivery.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-06Explain disk sizing inputs
Source locator: “The recommended machine configuration, disk sizes, and zones.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
- Procedure
- Check that the guide identifies boot and additional disk sizes and their roles and distinguishes a reference estimate from a minimum requirement.
- Expected observation
- The customer can choose the input with its purpose and scope understood.
- Keep as evidence
- Page section, input/default inventory and product-owner confirmation for the exact delivery.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-07Explain location inputs
Source locator: “The recommended machine configuration, disk sizes, and zones.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
- Procedure
- Check that the guide identifies recommended deployment zones and relevant regional assumptions and distinguishes a reference estimate from a minimum requirement.
- Expected observation
- The customer can choose the input with its purpose and scope understood.
- Keep as evidence
- Page section, input/default inventory and product-owner confirmation for the exact delivery.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-08Explain required ports
Source locator: “If the customer has to open any ports (particularly 80 or 443).”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- The product owner supplies the exact delivery network requirements.
- Procedure
- List whether the customer must open ports, particularly HTTP 80 or HTTPS 443; explain the required purpose and scope without assuming either port is necessary.
- Expected observation
- The guide identifies required ports and distinguishes optional or unnecessary exposure.
- Keep as evidence
- Network requirements table and guide section tied to the delivery.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-09Explain port defaults and customer actions
Source locator: “Whether the required ports are opened by default”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- The required-port inventory and deployment defaults are known.
- Procedure
- For each required port, state whether deployment opens it by default or the customer must select an authorized deployment option.
- Expected observation
- The customer knows which action is required and can compare the deployed state with the documented default.
- Keep as evidence
- Per-port default/action table and corresponding deployment UI reference.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-10List additional configuration commands
Source locator: “The document should list any additional commands needed to configure the product.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- A delivery-specific, supported configuration procedure has been identified.
- Procedure
- Check that every additional configuration command needed after deployment is listed with prerequisites, input placeholders, expected output and the point at which to stop.
- Expected observation
- The customer can identify all required configuration steps without inventing commands or substituting internal procedures.
- Keep as evidence
- Command inventory and corresponding guide sections; explicitly justified absence if none are needed.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-11Explain administrator access
Source locator: “If your product requires a login”
- Applies when
- When the product requires a login.
- Responsible role
- VibePackr documentation owner
- Before starting
- The supported customer administrator access route is defined for the delivery.
- Procedure
- Explain whether and how the customer reaches an administrator page or console URL, including the supported access route and prerequisites.
- Expected observation
- A first customer can identify the intended admin entry point; an unresolved bootstrap path is explicitly marked as pending.
- Keep as evidence
- Admin access section and delivery-specific first-customer access result when authorized testing occurs.
Current evidence note: The published guide describes C7 as pending. A local Admin connection demonstration does not close the frozen r232 first-customer bootstrap gap.
GS-12Explain how login credentials are obtained
Source locator: “how login credentials can be obtained.”
- Applies when
- When the product requires a login.
- Responsible role
- VibePackr documentation owner
- Before starting
- The product owner provides the supported first-customer credential provisioning route.
- Procedure
- Document where and how the authorized customer obtains credentials and which party is responsible; do not publish secret values or substitute internal test credentials.
- Expected observation
- The guide gives a usable, supported acquisition route or explicitly records the unresolved owner input.
- Keep as evidence
- Credential acquisition instructions and redacted first-customer verification record when available.
Current evidence note: C7 remains a declared first-customer gap for frozen r232. This checklist does not approve a new credential or bootstrap design.
GS-13Verify generated administrator passwords
Source locator: “the password must be auto-generated.”
- Applies when
- Only if a password is required to access an administrator page or console.
- Responsible role
- VibePackr documentation owner
- Before starting
- The product owner has confirmed that this password condition applies to the delivery.
- Procedure
- Record how the delivery meets the auto-generated-password requirement and request redacted evidence from the approved credential flow. If no password is used, record the reason for that applicability decision.
- Expected observation
- Any required administrator password is auto-generated; the applicability decision is supported.
- Keep as evidence
- Applicability rationale and redacted provisioning evidence, without the password itself.
Current evidence note: Conditional Google requirement. It does not prescribe VibePackr password authentication or authorize a new authentication design.
GS-14Document SSH access
Source locator: “Can connect to the VM instance using SSH.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- A supported customer SSH access route and prerequisites are identified.
- Procedure
- Check that the Getting Started page explains how the customer reaches the VM through the supported SSH route and recognizes connection failure.
- Expected observation
- The customer can follow a clear SSH access procedure for the exact delivery.
- Keep as evidence
- SSH guide section and separately recorded authorized connection result.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-15Document application health checks
Source locator: “Can check the status or health of the app.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr documentation owner
- Before starting
- Supported readiness and health observations are identified for the delivery.
- Procedure
- Check that the guide explains how to observe application status or health and distinguishes a running process from a ready, connected product.
- Expected observation
- The customer can identify a healthy state, an incomplete state and the next supported action.
- Keep as evidence
- Health guide section, expected observations and authorized delivery-specific results.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
GS-16Submit the draft URL for Partner Engineer feedback
Source locator: “email the URL of your draft to your assigned Partner Engineer for review and feedback.”
- Applies when
- Every VM product.
- Responsible role
- VibePackr review coordinator
- Before starting
- The Getting Started draft is reviewed and its assigned Partner Engineer is known.
- Procedure
- Have the authorized review coordinator send the draft URL to the assigned Partner Engineer and track feedback against the same document revision. This checklist does not send a message.
- Expected observation
- The assigned Partner Engineer receives the intended draft; feedback and its disposition can be traced.
- Keep as evidence
- Private correspondence reference, sent URL/revision, date and feedback log.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
03 · Preview and review access
15 mapped items. A row’s presence records document coverage only.
TEST-01Plan a customer-view preview
Source locator: “preview and test the product.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- Identify the product, image and deployment package versions under review.
- Procedure
- Include a preview of the listing and deployment experience in the review plan, using the customer-facing flow.
- Expected observation
- The planned preview identifies the exact delivery and what the customer will see.
- Keep as evidence
- Preview plan and exact product/image/package identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-02Confirm the uploaded deployment object
Source locator: “the Cloud Storage object must be uploaded and validated in Producer Portal.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The authorized package owner supplies the intended Cloud Storage object identity.
- Procedure
- Before scheduling deployment preview, request evidence that the correct Cloud Storage object was uploaded and selected in Producer Portal.
- Expected observation
- The uploaded object identity matches the intended deployment package.
- Keep as evidence
- Private object identity, package digest/version and portal upload record.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-03Confirm successful package validation
Source locator: “the Cloud Storage object must be uploaded and validated in Producer Portal.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The intended Cloud Storage object has an upload record.
- Procedure
- Check the portal record for successful validation of that exact uploaded object before marking preview prerequisites satisfied.
- Expected observation
- Producer Portal reports successful validation for the intended package revision.
- Keep as evidence
- Portal validation state, timestamp and matching object/package identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-04Confirm the preview project and authorized portal access
Source locator: “verify that you've selected the correct project and have the Editor (roles/editor) role for the project.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The public project ID and authorized review operator are identified.
- Procedure
- Document the Producer Portal entry for the public project. If access is unavailable, have the account owner verify the selected project and required Editor role before proceeding; this row does not grant access.
- Expected observation
- The authorized operator can reach the correct product project in Producer Portal.
- Keep as evidence
- Redacted project selector/access confirmation and operator identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-05Open the selected product deployment package
Source locator: “On the Overview page, click Deployment package.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- Portal access and the product identity are confirmed.
- Procedure
- In the planned preview procedure, select the named product and open Deployment package from its Overview page.
- Expected observation
- The package page belongs to the intended product and version.
- Keep as evidence
- Redacted product overview and package identity capture.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-06Enter deployment preview after validation
Source locator: “Verify that your deployment package was read and validated successfully and click Deployment preview.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The exact package was read and validated successfully.
- Procedure
- Include a gate that checks the successful read/validation state before the operator selects Deployment preview.
- Expected observation
- The preview opens for the same successfully validated package.
- Keep as evidence
- Portal read/validation state and preview identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-07Review preview settings before deployment
Source locator: “Review the deployment details and click Deploy.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- Preview prerequisites and a separately authorized test scope are recorded.
- Procedure
- Plan to review the deployment details before the authorized operator selects Deploy; retain the selected settings and resulting deployment identity.
- Expected observation
- The resulting preview uses the reviewed settings and has an observable deployment outcome.
- Keep as evidence
- Settings capture, deployment identity and outcome.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-08Verify behavior before leaving the preview
Source locator: “verified that it behaves as you expect”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- A preview deployment completed and its expected behavior is written down.
- Procedure
- Plan a comparison of observed behavior with the stated expectations before exiting the preview; record discrepancies rather than assuming deployment success proves behavior.
- Expected observation
- Observed results are linked to expected product behavior and all discrepancies are retained.
- Keep as evidence
- Behavior checklist, observations and discrepancy log for the preview deployment.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-09Record the Marketplace-owned image distinction
Source locator: “Cloud Marketplace uses your original version of the VM image for your testing.”
- Applies when
- When Use Marketplace owned images is enabled.
- Responsible role
- VibePackr test owner
- Before starting
- The image ownership setting and original image identity are known.
- Procedure
- Record that the vendor preview tests the original image while customers access a Google-owned copy; keep those identities distinct in the evidence.
- Expected observation
- Preview proof is explicitly scoped to the original image; customer-copy equivalence is not silently assumed.
- Keep as evidence
- Ownership setting, original image identity and any separately supplied customer-copy correspondence.
Current evidence note: The official test page explicitly distinguishes the two image paths. The exact setting for this review delivery remains owner input.
TEST-10Agree a current supported preview teardown procedure
Source locator: “To delete the preview deployment, open the Deployment Manager page and delete the deployment.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The test owner identifies preview resources and obtains the current Partner Engineer-supported teardown route.
- Procedure
- Record cleanup ownership, retained evidence and the supported teardown procedure before testing. The source names the legacy Deployment Manager deletion route; confirm the current route with the Partner Engineer instead of treating that text as a live deletion instruction.
- Expected observation
- The preview has an approved, current cleanup plan and its completion can be recorded without changing retained product artifacts.
- Keep as evidence
- Partner Engineer clarification, resource inventory, authorized cleanup procedure and later cleanup result.
Current evidence note: Legacy reference retained for traceability only. No deployment or deletion is executed by this guide.
TEST-11Plan every product end-to-end flow
Source locator: “We recommend you test each of your products' end-to-end flows”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The product owner lists supported customer flows and their expected outcomes.
- Procedure
- Prepare a test matrix for each end-to-end flow, connecting listing entry, deployment, configuration, use and completion to an exact delivery.
- Expected observation
- No supported flow is silently omitted; exclusions have an owner and rationale.
- Keep as evidence
- Flow inventory, delivery-bound test matrix and exclusions with rationale.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-12Obtain Partner Engineer readiness for the prescribed tests
Source locator: “as soon as your Partner Engineer informs you that your product is ready for end-to-end testing.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr review coordinator / Google Partner Engineer
- Before starting
- The assigned Partner Engineer and product delivery are identified.
- Procedure
- Record the Partner Engineer notification that the product is ready for the prescribed end-to-end testing before scheduling that test phase.
- Expected observation
- The test phase is tied to the Partner Engineer readiness notification.
- Keep as evidence
- Private notification reference, date, product identity and permitted test scope.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-13Verify access for every tester
Source locator: “verify that all testers have access to the product.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The intended tester roster is approved.
- Procedure
- Have the account owner confirm product access for every named tester before test execution; record unavailable access as pending.
- Expected observation
- Each listed tester can access the product under the intended account.
- Keep as evidence
- Tester roster and redacted access confirmations; no credentials.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-14Verify development-project viewer access when needed
Source locator: “If the product image(s) is not in your public project”
- Applies when
- When product images are outside the public project.
- Responsible role
- VibePackr test owner
- Before starting
- Image project placement and the intended tester roster are confirmed.
- Procedure
- Have the authorized project owner verify the documented viewer access for each tester in the development project containing the images. Record the access finding; do not create a grant from this checklist.
- Expected observation
- Every intended tester has the required access to the image-bearing development project, or the condition is justified as inapplicable.
- Keep as evidence
- Image-project identity, applicability rationale and redacted access confirmation.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-15Verify tester console and project membership
Source locator: “The testers need to be users of Cloud console, and must be added to the project.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The authorized project owner has the tester roster.
- Procedure
- Request confirmation that each tester is a Cloud console user and has been added to the applicable project before testing.
- Expected observation
- The roster has no unconfirmed console user or project membership entry.
- Keep as evidence
- Redacted roster-to-project membership confirmation.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
04 · Listing, pricing, support and terms
12 mapped items. A row’s presence records document coverage only.
TEST-16Check Marketplace search visibility
Source locator: “Ensure that the product card is visible in the search results”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The Partner Engineer-supported test visibility and tester access are confirmed.
- Procedure
- Plan to open Explore Marketplace, search for the product and record whether the intended product card appears.
- Expected observation
- The correct product card appears in the tester search results.
- Keep as evidence
- Search term, tester visibility context, date and result capture.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-17Check product card content
Source locator: “the information on the card is displayed correctly.”
- Applies when
- Each proposed VM product delivery.
- Responsible role
- VibePackr test owner
- Before starting
- The approved listing content and intended product identity are available.
- Procedure
- Compare the product card information with the intended listing content and record incorrect or clipped fields.
- Expected observation
- The card displays the intended product information correctly.
- Keep as evidence
- Card capture and field-by-field comparison to approved listing content.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-18Distinguish multiple product listings
Source locator: “If you have more than one product”
- Applies when
- When the vendor has more than one product.
- Responsible role
- VibePackr test owner
- Before starting
- The relevant product listing inventory is known.
- Procedure
- Compare each product card and ensure its content can be distinguished from the vendor's other products.
- Expected observation
- Customers can tell the listed products apart; applicability is documented.
- Keep as evidence
- Product comparison captures or a documented single-product rationale.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-19Check the product details header
Source locator: “The header is displayed with your name, category, estimated costs and Launch button.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The intended listing and estimate are available.
- Procedure
- From the product card, open the product details page and check the name, category, estimated costs and Launch button in the header.
- Expected observation
- All four header elements are present and match the intended listing.
- Keep as evidence
- Header capture, listing revision and expected name/category/cost values.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-20Check description and Learn more destination
Source locator: “a Learn more link that points to a specific product or service page on your website.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The intended product description and specific vendor product page are known.
- Procedure
- Compare the displayed description and follow Learn more to verify that it reaches the specific product or service page.
- Expected observation
- The intended description is shown and Learn more resolves to the relevant product page.
- Keep as evidence
- Description capture, link URL and observed destination.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-21Check the technology stack fields
Source locator: “The tech stack is displayed, with the product type, version, last updated timestamp, and category ID and components, if applicable.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The exact release metadata and applicable components are supplied.
- Procedure
- Check product type, version, last updated timestamp, category ID and any applicable components in the displayed technology stack.
- Expected observation
- The fields are present, applicable and consistent with the delivery identity.
- Keep as evidence
- Technology-stack capture and comparison to delivery metadata; reasons for inapplicable components.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-22Check price breakdown and pricing links
Source locator: “The Pricing section has the price breakdown, as well as working links to pricing and free trial.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The approved pricing model and any trial offer are identified.
- Procedure
- Check the price breakdown and follow the pricing and free-trial links. If no trial is offered, retain the approved applicability decision rather than inventing an offer.
- Expected observation
- Pricing information is visible and applicable links work; trial treatment matches the approved offer.
- Keep as evidence
- Pricing capture, resolved links and trial applicability rationale.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-23Check pricing accuracy and expansion
Source locator: “The pricing details are correct, and the Show more arrow expands properly.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The approved price schedule and estimation assumptions are available.
- Procedure
- Compare displayed pricing details with the approved schedule and expand Show more to check hidden details.
- Expected observation
- Pricing values are accurate and Show more exposes the expected details.
- Keep as evidence
- Before/after expansion captures and price comparison.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-24Clarify whether support is included in price
Source locator: “clearly specifies whether the support is bundled into the pricing.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The approved support and commercial terms are available.
- Procedure
- Check that Maintenance & support explicitly states whether support is included in the listed price.
- Expected observation
- A customer can determine whether the listed price includes support.
- Keep as evidence
- Maintenance & support capture and approved inclusion statement.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-25Describe support channels and hours
Source locator: “A description of available support channels and their hours of service.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The approved support offer identifies channels and operating hours.
- Procedure
- Check that Maintenance & support describes each available channel and its hours of service without implying an unapproved service level.
- Expected observation
- Support channels and service hours are explicit and match the approved offer.
- Keep as evidence
- Support section capture and approved channel/hour reference.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-26Check the support-site link
Source locator: “A link to your support site.”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The intended customer support entry point is known.
- Procedure
- Follow the link in Maintenance & support and verify that it reaches the intended customer support site.
- Expected observation
- The support link works and the customer can identify the support entry point.
- Keep as evidence
- Listed support URL and observed destination.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-27Check the EULA link
Source locator: “The Terms of service section includes a link to your End User License Agreement (EULA).”
- Applies when
- Each proposed VM product listing.
- Responsible role
- VibePackr test owner
- Before starting
- The legal owner supplies the applicable EULA and its approval state.
- Procedure
- Check that Terms of service links to the correct EULA and record its version and approval state; do not treat a public draft as an effective agreement.
- Expected observation
- The listing points to the intended EULA and unresolved legal approval is visible.
- Keep as evidence
- EULA link, version, observed destination and owner-provided approval reference.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
05 · Deployment and customer operations
14 mapped items. A row’s presence records document coverage only.
TEST-28Complete the launch inputs
Source locator: “Click Launch and fill in all of the applicable input fields to deploy the product.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The approved test scope, deployment prerequisites and intended input values are recorded.
- Procedure
- Plan to open the product details page, select Launch and complete every applicable input; retain chosen values without secrets.
- Expected observation
- The deployment form accepts the applicable values and omitted fields have a documented reason.
- Keep as evidence
- Redacted completed-input inventory and form validation observations.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-29Match deployment defaults to the pricing table
Source locator: “The product has the same default machine type and disk size as are specified in the pricing table”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The current listing pricing table and unchanged launch defaults are captured.
- Procedure
- Compare the default machine type and disk size in the launch form with those used in the product-details pricing table.
- Expected observation
- Both default values match the pricing-table configuration.
- Keep as evidence
- Side-by-side pricing table and launch defaults with listing/package revisions.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-30Check links in the deployment flow
Source locator: “Links work correctly.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The relevant launch/deployment screens and intended destinations are identified.
- Procedure
- Follow each customer-facing link in the deployment flow and record its destination and any failure.
- Expected observation
- Each link reaches its intended accessible destination.
- Keep as evidence
- Link inventory with source screen, URL, destination and result.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-31Check HTTP and HTTPS deployment choices
Source locator: “HTTP and HTTPS ports are checked/unchecked accurately.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- Documented network requirements and deployment defaults are available.
- Procedure
- Compare HTTP and HTTPS checked/unchecked states in the deployment form with the documented requirements and defaults.
- Expected observation
- Both choices reflect the intended network configuration; neither is assumed necessary by this checklist.
- Keep as evidence
- Form capture and per-port comparison to documented requirements.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-32Verify deployment on the default machine type
Source locator: “Deploy the product on a default machine type, and verify that the product is deployed successfully.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The test operator has a separately approved deployment scope and documented default settings.
- Procedure
- Include one default-machine deployment in the test plan and record its actual completion or failure before further checks.
- Expected observation
- The intended product deploys successfully using the documented default machine type.
- Keep as evidence
- Deployment identity, selected machine/disk settings, image/package identity and observed result.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-33Verify SSH connectivity to the deployed VM
Source locator: “You can SSH into the virtual machine instance.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The default deployment completed and supported SSH access is authorized.
- Procedure
- Plan an SSH connection through the documented customer route and record the exact VM reached.
- Expected observation
- The authorized tester can open an SSH session to the intended deployed VM.
- Keep as evidence
- Redacted connection result bound to deployment identity and access route.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-34Verify license metadata in the SSH session
Source locator: “Test the license key in an SSH session:”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The authorized tester has an SSH session to the intended VM and the expected license reference.
- Procedure
- Plan the official read-only license metadata check at the instance licenses endpoint, using the Metadata-Flavor: Google header, and compare the returned license reference with the expected delivery license.
- Expected observation
- The response identifies the intended license association; an empty or mismatched result is retained as a finding.
- Keep as evidence
- Redacted command/result record, VM identity and expected license reference.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-35Verify loaded application information
Source locator: “Application info is loaded.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The default deployment completed and its expected application information is identified.
- Procedure
- Check the post-deployment application information shown to the customer and compare it with the intended product and deployment.
- Expected observation
- Application information loads and identifies the correct deployed product.
- Keep as evidence
- Application-information capture and deployment identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-36Verify the applicable administrator login
Source locator: “If the application has admin URL, log into the Admin console with the username/password.”
- Applies when
- When the application exposes an administrator URL.
- Responsible role
- VibePackr test owner
- Before starting
- The exact delivery has a supported first-customer access and credential route.
- Procedure
- Record the administrator URL and approved authentication route; plan the login test using that route. The source describes username/password; if the product uses another mechanism, obtain Partner Engineer applicability confirmation instead of inventing passwords.
- Expected observation
- An authorized first customer can reach and use the intended Admin console, or the unresolved route/applicability remains explicit.
- Keep as evidence
- Redacted login result, access procedure and any Partner Engineer applicability decision.
Current evidence note: Frozen r232 first-customer bootstrap remains blocked at C7. Local repaired Admin candidate evidence is a separate scope and is not substituted for this result.
TEST-37Verify specified ports after deployment
Source locator: “Check that the specified ports are opened.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The declared port inventory and separately authorized network observation scope are available.
- Procedure
- Plan a comparison of observed port exposure with the documented specified ports after deployment, retaining the network context.
- Expected observation
- Specified ports are open in the expected scope, with unexpected results recorded.
- Keep as evidence
- Port observation record, source/destination context and comparison to the declared configuration.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-38Repeat the deployment checks across instance sizes
Source locator: “Repeat above steps for different instance sizes (especially large and small) and regions.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- The product owner and Partner Engineer establish supported small and large instance test choices.
- Procedure
- Include different instance sizes, especially small and large, in the matrix and repeat the applicable deployment checks for each.
- Expected observation
- Each selected size has its own deployment and post-deployment result; untested sizes are visible.
- Keep as evidence
- Size matrix with configuration, delivery identity, per-check results and exclusions.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-39Repeat the deployment checks across regions
Source locator: “Repeat above steps for different instance sizes (especially large and small) and regions.”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- Supported regions and the authorized test matrix are agreed.
- Procedure
- Include multiple agreed regions and repeat the applicable deployment checks in each; record the exact region and zone.
- Expected observation
- Each selected region has a traceable result; a single-region result is not presented as all-region proof.
- Keep as evidence
- Region/zone matrix with delivery identity, configuration, per-check results and exclusions.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-40Repeat checks on cloned instances
Source locator: “Repeat the above steps with cloned instances (cloned hard drives).”
- Applies when
- Each proposed VM deployment package.
- Responsible role
- VibePackr test owner
- Before starting
- A supported cloning route, test scope and cleanup disposition are agreed.
- Procedure
- Add cloned instances or cloned hard drives to the plan and repeat the applicable deployment-flow checks against their recorded lineage.
- Expected observation
- The cloned-instance path has its own results; original-instance proof is not reused as clone proof.
- Keep as evidence
- Original-to-clone identity mapping, per-check results and cleanup disposition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
TEST-41Test every documented post-deployment step
Source locator: “then you must also test these steps”
- Applies when
- When the Getting Started guide specifies post-deployment next steps.
- Responsible role
- VibePackr test owner
- Before starting
- The delivery-bound Getting Started revision and post-deployment step inventory are identified.
- Procedure
- Map every documented post-deployment step to an authorized test and record its actual result, including required AI, storage, administrator and health steps when present.
- Expected observation
- All applicable next steps are tested so successful deployment completion is supported; untested steps remain pending.
- Keep as evidence
- Guide-step-to-result crosswalk with exact delivery and document revision, outputs and unresolved findings.
Current evidence note: The public guide identifies pending customer AI, storage and administrator boundaries. Recorded local demonstrations do not establish completion of those steps on the review delivery.
06 · Component review, final review and publication
26 mapped items. A row’s presence records document coverage only.
SUB-01Reconcile listing prerequisites
Source locator: “reviewed and met all the requirements for listing your product.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The current official listing-requirements inventory and exact product are identified.
- Procedure
- Review the listing prerequisite mapping and request evidence for each applicable requirement; unresolved rows remain pending before submission.
- Expected observation
- The listing prerequisite set has itemized evidence and an accountable disposition for every applicable requirement.
- Keep as evidence
- Completed prerequisite crosswalk, supporting private evidence references and unresolved items.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-02Reconcile packaging prerequisites
Source locator: “reviewed and met all the requirements for packaging your product.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The current official packaging-requirements inventory and exact image/package are identified.
- Procedure
- Review the packaging prerequisite mapping against the exact image and deployment package; do not use documentation existence as package compliance evidence.
- Expected observation
- Every applicable packaging requirement has a delivery-bound result or explicit unresolved disposition.
- Keep as evidence
- Packaging crosswalk, exact image/package identities and private verification references.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-03Confirm payment setup
Source locator: “Configure payments so that you can be paid for your product's usage.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr commercial owner
- Before starting
- The authorized commercial owner and payments configuration scope are identified.
- Procedure
- Request the commercial owner's confirmation that the required payment setup is complete for the product and legal entity. Keep financial and account data in private records.
- Expected observation
- The submission has an owner-confirmed payment setup record, with unresolved items visible.
- Keep as evidence
- Private setup completion reference, legal-entity/product association and commercial owner confirmation.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-04Reconcile end-to-end results before submission
Source locator: “Test your product end-to-end.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The exact delivery, authorized test matrix and recorded results are available.
- Procedure
- Review every applicable preview, listing, deployment and post-deployment row before submission. Keep unsuccessful, not-run and inapplicable cases distinct.
- Expected observation
- The end-to-end submission record reflects actual results, not a documentation completion score.
- Keep as evidence
- Delivery-bound test matrix, unresolved findings and owner decisions for exclusions.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-05Obtain the Product Details component review
Source locator: “Product details”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The intended Product Details revision and its prerequisite records are identified.
- Procedure
- Include Product Details in the component-review checklist and retain the corresponding Producer Portal result before publication.
- Expected observation
- The exact component revision has a traceable review state; submission and approval are recorded separately.
- Keep as evidence
- Portal component name, revision, state, date and any required changes.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-06Obtain the Pricing component review
Source locator: “Pricing”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The intended Pricing revision and its prerequisite records are identified.
- Procedure
- Include Pricing in the component-review checklist and retain the corresponding Producer Portal result before publication.
- Expected observation
- The exact component revision has a traceable review state; submission and approval are recorded separately.
- Keep as evidence
- Portal component name, revision, state, date and any required changes.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-07Obtain the Deployment Package component review
Source locator: “Deployment package”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The intended Deployment Package revision and its prerequisite records are identified.
- Procedure
- Include Deployment Package in the component-review checklist and retain the corresponding Producer Portal result before publication.
- Expected observation
- The exact component revision has a traceable review state; submission and approval are recorded separately.
- Keep as evidence
- Portal component name, revision, state, date and any required changes.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-08Track component reviews independently
Source locator: “You can submit the following reviews in any order”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The Product Details, Pricing and Deployment Package review rows are present.
- Procedure
- Plan component reviews in the order appropriate for their readiness, while tracking each state separately. Do not treat one completed review as completion of the other components.
- Expected observation
- The review tracker permits independent ordering and identifies which component reviews remain open.
- Keep as evidence
- Component review tracker with independent states, revisions and next actions.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-09Track Google installation verification
Source locator: “verifying that your image deploys and uninstalls successfully”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace review team
- Before starting
- The exact submitted image and Google review record are identified.
- Procedure
- Reserve a field for Google's image deployment verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
- Expected observation
- Google's image deployment verification outcome and any requested changes are traceable to the submitted image.
- Keep as evidence
- Google review outcome or correspondence reference, image identity and finding disposition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-10Track Google uninstallation verification
Source locator: “verifying that your image deploys and uninstalls successfully”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace review team
- Before starting
- The exact submitted image and Google review record are identified.
- Procedure
- Reserve a field for Google's image uninstallation verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
- Expected observation
- Google's image uninstallation verification outcome and any requested changes are traceable to the submitted image.
- Keep as evidence
- Google review outcome or correspondence reference, image identity and finding disposition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-11Track Google unit testing
Source locator: “running unit tests”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace review team
- Before starting
- The exact submitted image and Google review record are identified.
- Procedure
- Reserve a field for Google's unit testing result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
- Expected observation
- Google's unit testing outcome and any requested changes are traceable to the submitted image.
- Keep as evidence
- Google review outcome or correspondence reference, image identity and finding disposition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-12Track Google vulnerability scanning
Source locator: “scanning your VM image for vulnerabilities”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace review team
- Before starting
- The exact submitted image and Google review record are identified.
- Procedure
- Reserve a field for Google's VM image vulnerability scanning result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
- Expected observation
- Google's VM image vulnerability scanning outcome and any requested changes are traceable to the submitted image.
- Keep as evidence
- Google review outcome or correspondence reference, image identity and finding disposition.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-13Track automatic validation after package upload
Source locator: “after you upload it”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace validation service
- Before starting
- The exact uploaded package revision is identified.
- Procedure
- Record the portal result of the automatic deployment-package validation triggered by upload. Keep uploading and successful validation as separate states.
- Expected observation
- The upload has a corresponding automatic validation result for the same package.
- Keep as evidence
- Upload record, package identity and automatic validation state.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-14Track validation for every package update
Source locator: “each time that you make a subsequent update to the package.”
- Applies when
- Whenever the deployment package is updated.
- Responsible role
- Google Cloud Marketplace validation service
- Before starting
- The prior and updated package revisions are identified.
- Procedure
- Record the automatic validation result for each subsequent package update; do not carry a prior revision's success into the updated revision.
- Expected observation
- Every updated revision has its own validation result.
- Keep as evidence
- Revision history, update identity and per-revision validation states.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-15Confirm portal completion after package validation
Source locator: “it marks this review as complete in Producer Portal.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- Google Cloud Marketplace validation service
- Before starting
- Successful validation of the current package is evidenced.
- Procedure
- Check the Deployment Package review state that Producer Portal marks complete after successful validation; retain its exact revision.
- Expected observation
- The portal completion state corresponds to successful validation of the intended current package.
- Keep as evidence
- Portal completion capture and matching validation/package identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-16Test after package validation and before publication submission
Source locator: “thoroughly test your product after validation is complete”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The current package validation is complete and its identity is fixed.
- Procedure
- Schedule thorough product tests after validation and before submitting for publication, and bind the results to that validated revision.
- Expected observation
- The post-validation test results apply to the package being submitted for publication.
- Keep as evidence
- Validated package identity, dated test matrix and recorded results before publication submission.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-17Gate private publication on component approvals
Source locator: “After Google has approved your product's component reviews”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- All component-review states and exact revisions are available.
- Procedure
- Check that Google has approved the product component reviews before the coordinator plans private publication for final testing and review.
- Expected observation
- Private publication is gated by the required component approvals, with unresolved reviews visible.
- Keep as evidence
- Component approval references, revision binding and private-publication readiness decision.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-18Plan private Publish for Google final review
Source locator: “Click Publish. This notifies Google that your product is ready for final review before publication.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- Google component approvals and separately authorized submission action are recorded.
- Procedure
- In the authorized submission procedure, open the product Overview in Producer Portal and select Publish to notify Google for final testing and review. Record this as private publication, not public launch.
- Expected observation
- Google is notified for final review and the product is privately published for that stage.
- Keep as evidence
- Private Publish confirmation, date, delivery identity and Google final-review reference.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-19Identify the review affected by a requested change
Source locator: “Navigate to the page you'd like to make changes to.”
- Applies when
- When a product mistake is found or Google requests a change after submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The requested change, relevant page and submitted revision are identified.
- Procedure
- Record the correction request and identify the exact product page and component review affected before planning the change.
- Expected observation
- Each requested change has an identified target and affected review.
- Keep as evidence
- Change request, page/component mapping and prior submitted revision.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-20Acknowledge the resubmission consequence
Source locator: “Click Acknowledge to acknowledge that you must re-submit the corresponding review”
- Applies when
- When changing a product page after submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- The affected review and authorized change scope are identified.
- Procedure
- Include the Acknowledge step in the change procedure so the owner explicitly accepts that the corresponding review must be resubmitted.
- Expected observation
- The change record shows acknowledgment of the required resubmission.
- Keep as evidence
- Acknowledgment record and affected review identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-21Record the intended post-submission changes
Source locator: “Make any intended changes to your product.”
- Applies when
- When an authorized post-submission correction is needed.
- Responsible role
- VibePackr review coordinator
- Before starting
- The exact requested change and corresponding review are identified and acknowledged.
- Procedure
- Have the responsible owner apply only the intended correction through the approved change procedure; preserve before/after revision identities in the review record.
- Expected observation
- The changed revision corresponds to the intended correction and its scope is reviewable.
- Keep as evidence
- Change summary, before/after identities and owner authorization reference.
Current evidence note: This is a review-process checklist. It does not authorize changes to the frozen Golden or product artifacts.
SUB-22Resubmit the affected component review
Source locator: “Re-submit the affected review for approval.”
- Applies when
- After an acknowledged post-submission change.
- Responsible role
- VibePackr review coordinator
- Before starting
- The changed revision and affected review are recorded.
- Procedure
- Include resubmission of the affected review in the authorized submission plan and retain the new approval result separately from the previous revision.
- Expected observation
- The updated revision has a resubmission record and its own review disposition.
- Keep as evidence
- Resubmission reference, changed revision, review outcome and remaining feedback.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-23Gate public launch on all review approvals
Source locator: “After all reviews have been approved”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- Component and final-review results for the exact intended delivery are available.
- Procedure
- Verify all review approvals before planning public launch; private publication and document completion do not satisfy this gate.
- Expected observation
- The public-launch checklist has complete review approval references for the intended delivery.
- Keep as evidence
- All-review approval matrix, final-review outcome and delivery identity.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-24Plan Enable public display
Source locator: “Click Enable public display.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- All reviews are approved and the product owner authorizes public launch separately.
- Procedure
- In the authorized launch procedure, open the product Overview in Producer Portal and select Enable public display.
- Expected observation
- The portal presents the next public-launch confirmation for the approved product.
- Keep as evidence
- Portal action record tied to the approved delivery and launch authorization.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-25Resolve a missing Enable public display control
Source locator: “If you don't see this button, verify that you've published your product privately.”
- Applies when
- When Enable public display is not visible.
- Responsible role
- VibePackr review coordinator
- Before starting
- The product Overview and current publication state are known.
- Procedure
- Check the private-publication record first and route any remaining portal-state mismatch to the review coordinator or Partner Engineer; do not infer public readiness from a missing control.
- Expected observation
- The missing-control finding is tied to the actual private-publication state and an explicit next action.
- Keep as evidence
- Portal state capture, private Publish record and any clarification.
Current evidence note: Not yet evidenced for the exact Marketplace review delivery.
SUB-26Record the final Make public action
Source locator: “Click Make public.”
- Applies when
- Every proposed VM product submission.
- Responsible role
- VibePackr review coordinator
- Before starting
- All reviews are approved, private review is complete and the exact public launch is authorized.
- Procedure
- Include Make public as the final authorized portal action after Enable public display; verify and record the resulting public listing instead of assuming the action alone proves availability.
- Expected observation
- The approved product is publicly visible and the actual publication state is recorded.
- Keep as evidence
- Make public confirmation, public listing URL, observed visibility, timestamp and delivery identity.
Current evidence note: Public website documentation is available. This is not evidence that the Marketplace product has been approved or made public.
Source scope and remaining dependencies
Five official pages checked 2026-10-04. Read their scope and revision dates. Linked specialized policies and deployment instructions still need their responsible owner’s assessment. Private or newly issued Google requirements belong in the workbook’s additional-requirements section.
Some official pages retain legacy tools or version wording. Record the stated requirement and obtain the current supported procedure from the assigned Partner Engineer. This guide does not authorize a legacy deletion recipe, a new privilege grant, or rebuilding the frozen image.